Thomson Reuters confirms cyberattack exposed court records in 11 states, Ontario and U.S. Virgin Islands
Thomson Reuters has confirmed a March 2026 cyberattack on its C-Track system that exposed court documents and personal information across 11 U.S. states, the U.S. Virgin Islands and Ontario, Canada.
In a brief announcement published earlier this week, Thomson Reuters said it detected unauthorized activity in one of its cloud environments on June 30. An investigation subsequently determined that an unauthorized threat actor broke in and obtained some C-Track files. C-Track is a court case-management tool used by courts to manage cases, filings, hearings and schedules.
The affected jurisdictions include Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, Ohio, New Hampshire and Wyoming, as well as the U.S. Virgin Islands and Ontario. Ontario's three Chief Justices confirmed the incident and said Thomson Reuters notified the province's Ministry of the Attorney General on July 23. Exposed records include court records and personal information.
Thomson Reuters said a more detailed investigation is underway and that all relevant authorities have been notified. The company has not yet determined exactly what information was accessed or how many people were affected. There is currently no evidence of identity theft resulting from the incident, and no indication that systems handling court-related financial transactions were affected.
C-Track remains operational, according to the company. No threat actor has yet claimed responsibility or threatened to leak the files on the dark web. "There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson said. "Our products and services remain fully operational and are safe to continue to use. Independent cybersecurity experts assisted in the investigation and validated the remediation measures implemented."